TUGC
OutcomesPricingFAQ
Sign inFind my creators

TUGC Legal Terms

These Terms govern your access to and use of TUGC. They include our terms of service, our privacy notice, our use of cookies, our acceptable use rules, and the data-processing terms applicable to business customers. They form a single, integrated agreement between you and us.

Effective Date: May 1 2026   ·   Last Updated: May 20 2026


1. About TUGC and these Terms

Trendy UGC (also referred to as "TUGC") is a software-as-a-service platform that helps brands and agencies discover, evaluate, and contact Instagram creators. In these Terms, "Trendy UGC," "we," "us," and "our" refer to SocialVibe OÜ, registration number 17350611, with registered address Harju maakond, Tallinn, Lasnamäe linnaosa, Tähesaju tee 21-114. You can reach us at agent@heytrendy.app for general matters.

These Terms govern your access to and use of the TUGC website, platform, software, content, and related services (collectively, the "Services"). They include our privacy notice, our use of cookies and similar technologies, our acceptable-use rules, the data-processing terms applicable to business customers, our subprocessor list, and our checkout disclosures. They form one integrated agreement; references to "these Terms" mean the whole of this document.

By accessing or using the Services, creating an account, or making a purchase, you agree to these Terms. If you use the Services on behalf of a company or other entity, you represent and warrant that you have authority to bind that entity, and "you" and "your" refer to that entity as well.

These Terms apply both to consumers (natural persons acting outside their trade, business, craft, or profession) and to business customers. Where any provision conflicts with mandatory consumer-protection law applicable to a particular consumer, that mandatory law prevails for that consumer and the remaining provisions continue to apply.

2. Eligibility and your account

You may use the Services only if you are legally able to enter into a binding agreement and are not prohibited from using the Services under applicable law.

You are responsible for maintaining the confidentiality of your account credentials and for all activity that occurs under your account. You agree to provide accurate, current, and complete information and to keep it updated, and to notify us promptly of any unauthorised use of your account.


Workspace administration. Trendy UGC organises usage around workspaces. The person who creates a workspace (the "Workspace Owner") may invite additional users ("Workspace Members") to that workspace by email and may assign roles to those users. The Workspace Owner is responsible for: (a) ensuring it has authority to bind the organisation to these Terms and to invite Workspace Members; (b) determining what Workspace Members may do within the workspace; (c) the use of any creator data, lists, or exports generated within the workspace; and (d) providing Workspace Members with any privacy notices required by applicable law in respect of the Workspace Owner's processing of their personal data. Where Workspace Members access Trendy UGC, they are also subject to these Terms in their individual capacity.


3. What the Services do

TUGC helps you discover, evaluate, and contact UGC creators. Features may include creator search and discovery, list and campaign management, communications tooling, analytics, and integrations with third-party platforms.

The Services rely on publicly available information about creators and do not access non-public, authenticated, or password-protected content on third-party platforms. We do not scrape or otherwise circumvent the technical or legal protections of third-party platforms.

We may modify, update, improve, suspend, or discontinue all or part of the Services at any time, subject to applicable law. For paid features that we discontinue, we will provide reasonable advance notice and, where appropriate, a pro-rata refund of pre-paid fees attributable to the discontinued feature.

4. Personal data we collect

We collect personal data in the following ways.

4.1 Information you give us

first and last name;

email address;

password or other authentication credentials;

company name, role, team, or workspace information;

information you submit in forms, demo requests, onboarding flows, waitlists, support tickets, surveys, or correspondence;

any other information you choose to provide.

4.2 Account and service data

account, organisation, and workspace identifiers;

subscription status, plan, and billing interval;

settings, preferences, configurations, saved searches, lists, and feature-usage records;

logs, diagnostic events, session activity, and usage history;

records of administrative, billing, and support interactions.

4.3 Payment and billing information

If you purchase a subscription or usage-based services, payment is processed by Stripe, Inc. ("Stripe"), which acts as an independent data controller for its own fraud-prevention, regulatory, and compliance purposes. Stripe's processing is governed by Stripe's privacy policy at https://stripe.com/privacy.

In connection with billing, we and our service providers may process:

billing email address and payer name;

billing country, address, postal code, and tax identification, where applicable;

selected plan, billing interval, pricing, currency, and invoice details;

transaction, customer, and subscription identifiers and related metadata;

payment, invoice, renewal, cancellation, refund, and dispute status;

limited payment-method metadata (card brand, expiry month and year, last four digits);

records relating to refund requests, billing issues, payment disputes, chargebacks, fraud checks, and compliance reviews.

Full payment-card numbers and card security codes are not stored on TUGC servers. Card data is transmitted directly to Stripe's PCI-DSS Level 1 environment using Stripe Elements or equivalent Stripe-hosted fields, so card data does not transit or persist in TUGC systems.

4.4 Information collected automatically

IP address;

browser type and version;

device type and operating system;

language settings and approximate location at country or region level (derived from IP; we do not collect precise geolocation);

website interactions, clicks, pages viewed, session duration, referring URLs, and timestamps;

cookie and similar-technology identifiers (see Section 7).

4.5 Information from third parties

Stripe, in connection with payments, billing events, subscriptions, invoices, refunds, and disputes;

analytics, hosting, security, support, communications, and CRM providers (see Section 9);

integrations or connected services you choose to use with TUGC;

publicly available sources or business-information providers, where permitted by law.

5. Personal data about UGC creators

TUGC enables customers to discover UGC creators. To provide this functionality we collect and index limited, publicly available information about creators from public sources, including public profiles on social-media platforms and other publicly accessible web pages. The information processed may include:

public handle or username and display name;

publicly displayed profile image, biography, and links;

public engagement and audience metrics (e.g., follower count, average views, engagement rate) as published by the platform or computed from public data;

public content metadata (e.g., post URLs, captions, hashtags, dates, topics);

publicly available contact channels (e.g., a business email a creator has chosen to publish on a public profile).

We do not collect private or non-public information about creators and we do not bypass authentication, scraping protections, rate limits, or platform terms of service to obtain creator data.

Where the GDPR or UK GDPR applies, our legal basis for this processing is our legitimate interests under Article 6(1)(f) — operating and providing a creator-discovery platform built on publicly available information — balanced against creators' rights and freedoms, and our legal obligations under Article 6(1)(c) where applicable. A summary of our Legitimate Interests Assessment is available on request to agent@heytrendy.app.

Article 14 information for creators. If you are a creator and want to know what information about you is held in TUGC, object to that processing, request correction, or request deletion or removal from the index, please email agent@heytrendy.app. We will respond within the timeframes set out in Section 14. Where you object on grounds relating to your particular situation, we will stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.

Customer responsibilities. TUGC customers are independent data controllers in respect of any creator data they export or use outside the platform. Customers are responsible for complying with applicable law when contacting creators (see Section 18).

Automated processing of creator information. Trendy UGC uses automated processing to rank, score, and cluster creators based on the public information described above. This processing supports our customers' creator-discovery workflows and does not produce legal or similarly significant effects for creators. The factors considered include creator topics and content categories, audience size and engagement, and content fit with customer-defined criteria. If you are a creator and want to understand or object to how your public information is processed in Trendy UGC, please contact agent@heytrendy.app. 

6. How we use personal data and our legal bases

We use personal data for the following purposes:

to provide, operate, maintain, and improve the Services;

to create and manage accounts and authenticate users;

to process subscriptions, recurring billing, usage-based purchases, invoices, renewals, cancellations, and refunds through Stripe;

to provide customer support, troubleshooting, onboarding, and account management;

to send transactional, administrative, service-related, billing, and support communications;

to send marketing communications where we have a lawful basis, and from which you can opt out at any time;

to understand product usage and improve features, performance, usability, and reliability;

to operate creator discovery, indexing, ranking, and matching features;

to detect, prevent, and investigate fraud, abuse, unauthorised access, security incidents, and violations of these Terms;

to comply with legal, tax, regulatory, accounting, audit, and reporting obligations;

to establish, exercise, or defend legal claims.

Where the GDPR, the UK GDPR, or other laws that require an identified lawful basis apply, we rely on:

Performance of a contract (Art. 6(1)(b)) — to provide the Services, administer your account, and perform our contractual obligations to you;

Legitimate interests (Art. 6(1)(f)) — for service improvement, product analytics, customer support, fraud prevention, platform security, creator-discovery functionality, and protection of our legal rights;

Legal obligation (Art. 6(1)(c)) — to comply with applicable laws and lawful requests from public authorities;

Consent (Art. 6(1)(a)) — where required, including for certain cookies and optional marketing communications. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

7. Cookies and similar technologies

We use cookies, pixels, SDKs, local storage, and similar technologies (together, "cookies") to operate the website and Services, remember your settings, understand usage and performance, support security and fraud prevention, and — where you consent — for analytics and marketing. Only strictly necessary cookies are loaded by default; all non-essential cookies are loaded only after you give consent through our cookie banner. You can withdraw consent at any time through the cookie preference centre accessible from the website footer.

The cookies we use are listed in the table below.

Name

Provider

Category

Purpose

Duration

tugc_session

TUGC

Strictly necessary

Maintains your authenticated session

Session

tugc_csrf

TUGC

Strictly necessary

Cross-site request forgery protection

Session

tugc_cookie_consent

TUGC

Strictly necessary

Stores your cookie consent choices

12 months

tugc_lb

TUGC / hosting provider

Strictly necessary

Load balancing across servers

Session

tugc_prefs

TUGC

Functional

Stores UI preferences (language, theme)

12 months

_ga / _ga_*

Google Analytics 4

Analytics

Distinguishes users and sessions for analytics

24 months

_gid

Google Analytics 4

Analytics

Distinguishes users for analytics

24 hours

intercom-*

Intercom (if used)

Functional

In-app messaging and support widget

9 months

__stripe_mid / __stripe_sid

Stripe

Strictly necessary

Payment fraud prevention

1 year / 30 minutes

hubspotutk / __hssc / __hssrc / __hstc

HubSpot (if used)

Marketing

Marketing analytics and lead attribution

Up to 13 months

fr / _fbp

Meta (if used)

Marketing

Conversion measurement and advertising

Up to 90 days / 3 months

li_at / lidc / bcookie

LinkedIn (if used)

Marketing

Insight Tag and ad measurement

Up to 2 years

Some cookies are set by third parties such as analytics, support, and marketing providers; these third parties may use the cookies for their own purposes, including their own analytics and advertising. Where applicable, third-party cookies load only after you consent.

You can manage cookies through our cookie preference centre, by configuring your browser, or, for marketing cookies set by third parties, through industry opt-out tools such as the EDAA (https://www.youronlinechoices.eu/), the DAA (https://optout.aboutads.info/), and the NAI (https://optout.networkadvertising.org/). Disabling strictly necessary cookies will prevent parts of the Services from functioning.

There is no widely agreed standard for the browser Do-Not-Track signal, so we currently do not respond to it. We do honour the Global Privacy Control (GPC) signal where required by applicable law (see Section 15).

8. Stripe payments, Strong Customer Authentication, and fraud prevention

Website-based payments are processed by Stripe. By purchasing through the website, you authorise us and Stripe to charge the payment method you provide for the selected subscription plan or one-time purchase, any applicable recurring renewals, authorised usage-based charges or add-ons selected by you, and any applicable taxes and fees.

For payments made by customers in the European Economic Area, the United Kingdom, or Switzerland, Stripe applies Strong Customer Authentication (3-D Secure or equivalent) as required by PSD2 and the SCA-RTS. Authentication is performed between Stripe, your card issuer, and you; we receive only the outcome of that authentication.

Where Stripe Radar or similar fraud-prevention tooling is used to score transactions, the analysis is performed by Stripe acting as an independent controller. If a Radar decision blocks a transaction, you may contact us at agent@heytrendy.app. and we will, where reasonably possible, route the matter to Stripe for human review.

9. How we share personal data 

We share personal data with:

Stripe, for payment processing, recurring billing, invoicing, fraud prevention, refunds, and dispute handling;

service providers and subprocessors — cloud hosting, infrastructure, analytics, security, CRM, support, email delivery, and similar business service providers;

professional advisers (lawyers, auditors, accountants, consultants, insurers);

courts, regulators, law enforcement, tax authorities, or other recipients where required by law or reasonably necessary to protect rights, safety, security, or compliance;

recipients in connection with a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction.

U.S. state privacy laws (California, Colorado, Connecticut, Virginia, Utah and others). We do not "sell" or "share" personal information as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA) or under analogous state laws, and we have not done so in the preceding 12 months. We do not engage in targeted advertising or in profiling that produces legal or similarly significant effects about consumers. If this changes, we will update these Terms and provide the "Do Not Sell or Share My Personal Information" link required by Cal. Civ. Code § 1798.135(a).

10. International data transfers

Your personal data may be processed in countries other than your own. For transfers from the European Economic Area, the United Kingdom, or Switzerland to countries that have not received an adequacy decision, we rely on the European Commission's 2021 Standard Contractual Clauses (and, for UK transfers, the UK International Data Transfer Addendum) together with the supplementary safeguards required by the Schrems II ruling, including transfer impact assessments. Where applicable, we also rely on the EU-U.S. Data Privacy Framework and its UK and Swiss extensions for transfers to self-certified U.S. recipients. A copy of the relevant transfer mechanism is available on request to agent@heytrendy.app.

11. Data retention

We retain personal data for as long as reasonably necessary for the purposes set out in these Terms, including to provide the Services, maintain records, comply with legal obligations, resolve disputes, enforce agreements, and protect our legal interests. Our standard retention periods are:

Data category

Retention period

Reason

Account profile data

Duration of the account + 30 days

Account-closure grace period

Service usage logs / diagnostic events

13 months

Security incident investigation and SIEM rotation

Support tickets and correspondence

3 years from last interaction

Statute of limitations on contract claims; dispute resolution

Billing, invoice, tax records

7 years

Tax and accounting retention

Payment-dispute and chargeback records

18 months from resolution

Card-network rules and fraud defence

Marketing consent records

Until consent is withdrawn + 3 years

Demonstrate consent under Art. 7(1) GDPR

Cookie consent records

12 months

Re-prompt cadence under EDPB guidance

Creator-index data (publicly sourced)

Until the source is no longer public, the creator objects under Art. 21 GDPR, or we determine the record is stale

Maintain accuracy of discovery data

12. Data security and breach notification

We implement reasonable technical and organisational measures to protect personal data from unauthorised access, disclosure, alteration, loss, and destruction, including encryption in transit, encryption at rest for sensitive data, role-based access controls and least-privilege, multi-factor authentication for administrative access, centralised logging and monitoring with anomaly detection, vulnerability management with dependency scanning and periodic third-party penetration testing, encrypted backups with documented recovery procedures, personnel confidentiality obligations and security-awareness training, and a documented incident-response plan.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach affecting your data, we will notify you and the competent supervisory authority where and within the timeframes required by applicable law, including the 72-hour notification window under Article 33 GDPR where applicable.

13. Your privacy rights

Depending on your location and applicable law, you may have the right to:

request access to your personal data;

request correction of inaccurate or incomplete data;

request deletion of personal data;

object to or request restriction of certain processing, including processing based on legitimate interests;

request portability of your personal data;

withdraw consent where processing is based on consent;

opt out of marketing communications at any time;

lodge a complaint with a competent data protection authority.

14. How to exercise your rights

To exercise your rights, email agent@heytrendy.app or use the self-service privacy controls within your TUGC account. We will acknowledge your request within 10 business days and substantively respond within the timeframe required by applicable law (30 days under the GDPR and UK GDPR, extendable by 60 days for complex requests; 45 days under the CCPA/CPRA, extendable by 45 days). We may verify your identity before responding. You will not be discriminated against for exercising your rights.

15. U.S. state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another U.S. state that has enacted a comprehensive consumer privacy law, you may also have the right to know what personal information we collect, use, and disclose about you; to delete it, subject to statutory exceptions; to correct inaccurate information; to obtain a portable copy of it; to opt out of the sale or sharing of personal information and of targeted advertising and significant-effect profiling; to limit the use and disclosure of sensitive personal information; and to appeal a denial of a privacy request. We honour browser-based opt-out signals such as the Global Privacy Control where required by law. You may designate an authorised agent to make a request on your behalf, subject to identity verification. To submit a request, email agent@heytrendy.app.

16. Automated decision-making and children's privacy

Other than the fraud-prevention analytics performed by Stripe (Stripe Radar), described in Section 8, we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. The Services are not directed to children, and we do not knowingly collect personal data from children under the minimum age required by applicable law to use the Services independently. If you believe a child has provided us with personal data, please contact us at agent@heytrendy.app.

17. Acceptable use

You agree to follow the rules below when you use the Services. You may not, and may not permit others to:

use the Services in violation of any applicable law or regulation;

infringe any intellectual property, privacy, publicity, or other right of any person;

send unsolicited commercial communications or messages that violate anti-spam laws (CAN-SPAM, CASL, ePrivacy / PECR, or equivalent);

harass, threaten, defame, or discriminate against any person, including any creator surfaced through the Services;

transmit content that is unlawful, obscene, sexually explicit, abusive, or that depicts violence;

engage in fraud, phishing, social engineering, or deceptive practices;

promote or facilitate illegal activity (unlawful gambling, sale of controlled substances, weapons trafficking);

exploit, harm, or attempt to exploit or harm minors;

scrape, harvest, or extract data from the Services in bulk except through documented APIs and within published rate limits;

circumvent or attempt to circumvent access controls, rate limits, or technical protections of the Services;

introduce malware, viruses, worms, time bombs, or other malicious code;

probe, scan, or test the vulnerability of the Services without our prior written authorisation;

interfere with or disrupt the integrity or performance of the Services or any infrastructure connected to them;

use the Services to violate the terms of service of any third-party platform from which creator information is sourced.

To report abuse, security issues, or content that violates these rules, contact agent@heytrendy.app. We may investigate suspected violations, remove offending content, and suspend or terminate accounts in accordance with Section 26.

18. Creator outreach and your responsibilities as a customer

If you use the Services to contact, recruit, or engage creators, you are responsible for:

complying with all applicable laws governing direct marketing and electronic communications, including the EU ePrivacy Directive, the UK Privacy and Electronic Communications Regulations (PECR), the U.S. CAN-SPAM Act, Canada's Anti-Spam Legislation (CASL), and equivalent laws;

complying with applicable data-protection laws (GDPR, UK GDPR, CCPA/CPRA, and other state privacy laws), including providing required notices (such as the information required by Articles 13–14 GDPR at or before first contact) and respecting opt-outs and erasure requests;

complying with the terms of service of any third-party platform on which a creator's contact information was published or through which you communicate with the creator;

honouring any opt-out or do-not-contact request from a creator within the timeframes required by law;

where you act as a controller of creator personal data, ensuring you have a valid lawful basis for processing;

not using creator data for automated decision-making producing legal or similarly significant effects without an adequate legal basis and safeguards.

We may suspend or terminate your access if your outreach generates credible reports of abuse, spam complaints, or violations of third-party platform terms.


Export of creator data. When you export creator information from a Trendy UGC workspace (whether by file download, integration, or API), you do so as an independent controller of that exported data. From the moment of export, you are responsible for: (a) the lawful basis for any further processing; (b) providing creators with any notices required by applicable data-protection law (including the information required by Article 14 GDPR at or before first contact); (c) honouring opt-out, erasure, and similar requests; and (d) complying with any platform terms of service (including Instagram's Platform Policy and Meta's Platform Terms) applicable to the export and your downstream use.

19. Plans, subscriptions, taxes, and refunds

19.1 Plans and purchases

We may offer a free plan, recurring subscriptions, one-time purchases, and usage-based purchases (including workspace tokens, top-ups, and credits). The features, billing interval, usage terms, and pricing applicable to a plan are shown at checkout or within the Services. Prices may change from time to time, but changes will not apply retroactively to charges already processed unless disclosed and permitted by law.

19.2 EU / UK / Swiss consumer waiver of right of withdrawal

By completing your purchase, you expressly request immediate provision of the digital service and acknowledge that, once performance has begun with your consent, you lose the right of withdrawal in accordance with Article 16(m) of Directive 2011/83/EU (the Consumer Rights Directive) and equivalent national implementations (including, in the UK, Regulation 37(1) of the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013).

19.3 Automatic renewal

If you purchase a recurring subscription, it will automatically renew for successive billing periods at the then-current price shown at checkout or otherwise disclosed to you, unless you cancel before the next renewal date. By completing the purchase, you agree to that recurring billing arrangement.

California subscribers. The automatic-renewal terms (length of the subscription, recurring charges, billing cadence, and how to cancel) are presented in a clear and conspicuous manner at checkout, separately from other terms, and you must affirmatively accept them before being charged. We will send you an acknowledgement after purchase containing the renewal terms and a description of the cancellation policy. You may cancel an auto-renewing subscription at any time and without penalty through your in-product billing settings or by emailing agent@heytrendy.app; online cancellation is available to all subscribers who signed up online, in accordance with applicable U.S. federal and state automatic-renewal and negative-option laws. For free trials or promotional periods that convert to a paid subscription, we will provide the additional notices required by Cal. Bus. & Prof. Code § 17602(b).

19.4 Free trials

If we offer a free trial, the duration, post-trial price, and automatic conversion terms will be shown at checkout. Unless cancelled before the trial ends, your free trial will convert to a paid subscription and your payment method will be charged. We will send a reminder email at least three (3) days before the trial converts.

19.5 Cancellation

You may cancel your subscription at any time through the in-product billing flow, through Stripe-hosted billing management where applicable, or by emailing agent@heytrendy.app. Unless otherwise stated at checkout or required by law, cancellation takes effect at the end of the current paid billing period, and you will retain access until the end of that period. Cancellation prevents future renewals but does not automatically reverse or refund charges already processed, except as described in these Terms or required by law.

19.6 Refunds

Nothing in this Section limits any non-waivable refund or remedy you may have under mandatory consumer-protection law, including, for EU consumers, remedies under Directive (EU) 2019/770 on digital content and digital services; for UK consumers, Chapter 3 of Part 1 of the Consumer Rights Act 2015; and, for U.S. consumers, applicable state consumer-protection statutes.

You may request a refund by contacting agent@heytrendy.app. Refund requests are reviewed in good faith on a case-by-case basis. Factors we may consider include duplicate charges, technical malfunctions that materially prevented use, material non-delivery, billing errors, and consumer rights under mandatory law. Approved refunds are processed back to the original payment method where possible.

19.7 Usage-based purchases and credits

Workspace token balance and usage-based purchases. Some features of Trendy UGC are paid for through a workspace-shared token balance. Subscription plans include a monthly token allowance that resets at the start of each billing period. Unused monthly tokens do not roll over. Where your usage exceeds the monthly allowance, usage is charged at the overage rate shown at checkout. You may purchase additional tokens (top-ups) at the price shown at checkout; top-ups expire after 1 month. Consumed tokens are non-refundable except where required by mandatory consumer law. On cancellation, unused subscription tokens are forfeited at the end of the current billing period. The exact token pricing, overage rules, and expiry are shown at checkout and within your account workspace settings.

19.8 Taxes

Prices shown at checkout are exclusive of value-added tax (VAT), goods-and-services tax (GST), sales tax, and similar transaction taxes unless expressly stated otherwise. Where we are required to collect such taxes (for example, VAT on sales to consumers in the EU/UK under the EU VAT One-Stop-Shop scheme), they will be added at checkout and remitted to the relevant authority. Where the reverse-charge mechanism applies (typically for business customers in the EU/UK), you are responsible for self-accounting for VAT/GST. You remain responsible for any taxes that are not based on our net income and that we are not required by law to collect.

20. Intellectual property and your content

The Services, including all software, code, interfaces, content, branding, design, text, graphics, logos, and related materials, are owned by us or our licensors and are protected by intellectual property laws. Subject to these Terms and any applicable subscription plan, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable right to access and use the Services for your internal business purposes. If you provide feedback or suggestions, we may use them without restriction and without compensation.

If you submit, upload, transmit, connect, or otherwise make available content, data, prompts, materials, or other inputs through the Services ("Customer Content"), you represent and warrant that you have all rights and permissions necessary to do so. You retain ownership of your Customer Content, but you grant us a non-exclusive, worldwide, limited licence to host, reproduce, process, transmit, adapt, and use Customer Content solely as necessary to operate, secure, maintain, improve, and support the Services and to comply with law.

21. Third-party platforms

The Services depend on, and surface information from, third-party platforms (including social-media platforms). We do not control those platforms, and our ability to provide information about creators may be affected by changes to those platforms' policies, APIs, or the availability of public information. We are not responsible for the accuracy or availability of third-party information, and your use of any creator's content remains subject to that creator's rights and the terms of the platform on which the content was published.

22. Availability, disclaimers, and limitation of liability

We aim to keep the Services available and functional but do not guarantee uninterrupted, error-free, or completely secure operation. To the fullest extent permitted by law, the Services are provided on an "as is" and "as available" basis without warranties of any kind, whether express, implied, statutory, or otherwise, including implied warranties of merchantability, fitness for a particular purpose, non-infringement, and availability.

To the fullest extent permitted by law, we will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenues, business opportunities, goodwill, data, or anticipated savings arising out of or related to the Services. Subject to the carve-outs below, our aggregate liability arising out of or relating to the Services or these Terms in any 12-month period will not exceed the greater of (a) the total amounts you paid us for the Services during the 12 months preceding the event giving rise to the claim, or (b) USD 500.

Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law, including (i) liability for death or personal injury caused by negligence; (ii) liability for fraud or fraudulent misrepresentation; (iii) for EU/UK consumers, statutory guarantees and conformity remedies under the EU Digital Content/Services Directive and the UK Consumer Rights Act 2015; and (iv) any other liability that cannot be excluded under mandatory law.

23. Indemnification

If you use the Services as a business customer (and not as a consumer), you agree to defend, indemnify, and hold harmless TUGC and its affiliates, directors, officers, employees, and agents from and against any third-party claims, damages, liabilities, and reasonable expenses (including reasonable legal fees) arising out of or relating to: (a) your Customer Content; (b) your use of the Services in violation of these Terms or applicable law; (c) your communications with creators or other third parties through or as a result of the Services; or (d) your breach of any representation or warranty in these Terms.

24. Data processing for business customers

This Section 24 applies where you use the Services on behalf of an organisation and our processing of personal data under these Terms is carried out on the organisation's behalf. In that situation the organisation is the controller and TUGC is the processor in respect of that personal data ("Customer Personal Data"). Where TUGC is itself a controller — including in respect of account data of authorised users, billing records, and fraud-prevention activity — the other provisions of these Terms apply and this Section 24 does not.

Instructions. We will process Customer Personal Data only on documented instructions from the customer, including with regard to international transfers, unless we are required to do so by law to which we are subject. Your use of the Services in accordance with these Terms is your initial documented instruction.

Confidentiality. We will ensure that persons authorised to process Customer Personal Data are bound by appropriate confidentiality obligations.

Security. We will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk; a summary is in Section 12.

Subprocessors. The customer authorises TUGC to engage subprocessors. We will impose data-protection obligations on each subprocessor that are no less protective and will remain liable for their acts and omissions. We will give at least 30 days' prior notice of any addition or replacement of a subprocessor; you may object on reasonable data-protection grounds within 30 days, and if we cannot resolve the objection in good faith, you may terminate the affected portion of the Services and receive a pro-rata refund of pre-paid fees.

Assistance with data-subject requests. We will, to the extent legally permitted, promptly notify you if we receive a request from a data subject to exercise their rights and will assist you by appropriate technical and organisational measures.

Personal data breaches. We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably required for your breach-notification obligations.

DPIAs and prior consultation. We will provide reasonable assistance with data-protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR.

International transfers. Where we transfer Customer Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the European Commission's 2021 Standard Contractual Clauses (Modules 2 and 3 as applicable) and, for UK transfers, the UK International Data Transfer Addendum are deemed incorporated. Clause 9(a) Option 2 (general written authorisation, 30 days' notice) applies; Clause 17 governing law is the law of Estonia; Clause 18 forum is the courts of that Member State.

Audits. We will make available the information reasonably necessary to demonstrate compliance with this Section 24. This obligation may be satisfied by providing third-party audit reports (SOC 2 Type II, ISO 27001, or equivalent) where available. On at least 30 days' prior written notice and not more than once per 12-month period (except following a confirmed personal data breach), you may conduct or commission an audit subject to reasonable confidentiality and security obligations and without unreasonable disruption.

Return or deletion. At your choice, we will delete or return Customer Personal Data after the end of the provision of services and delete existing copies, unless storage is required by applicable law.

CCPA / CPRA service-provider terms. To the extent the CCPA/CPRA applies, TUGC acts as a "service provider" within the meaning of Cal. Civ. Code § 1798.140(ag). We will not (a) sell or share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than performing the Services or as otherwise permitted by the CCPA/CPRA; (c) retain, use, or disclose it outside the direct business relationship; or (d) combine it with personal information from other sources except as permitted by Cal. Civ. Code § 1798.140(ag)(1)(D)(iii). We will notify you if we determine we can no longer meet our CCPA/CPRA obligations.

In the event of any conflict between Section 24 and the other provisions of these Terms in respect of the processing of personal data, Section 24 prevails; the SCCs prevail over both Section 24 and the rest of these Terms in respect of transfers covered by the SCCs.

25. Checkout and billing disclosures

The following disclosures are presented at checkout and after purchase. They form part of these Terms.

25.1 Recurring subscription disclosure (next to the CTA)

By clicking Subscribe, you authorise TUGC, through Stripe, to charge your payment method on the amount of the chosen plan today and to automatically renew this subscription after 1 month of usage until you cancel. Your subscription will renew after 1 month thereafter unless cancelled before the renewal date. You can cancel anytime in your account billing settings; cancellation takes effect at the end of the current paid period.

25.2 One-time purchase disclosure

By completing your purchase, you authorise a one-time charge on the amount shown at checkout. Additional purchases, including add-ons or credits, will only be charged when selected by you.

25.3 Usage-based / credit purchase disclosure

This purchase provides access to usage-based services, credits, or similar units as described at checkout. The applicable price for plans is shown at checkout and usage terms are shown before payment. Unless otherwise stated, used services and consumed usage are non-refundable.

25.4 Free-trial disclosure

After the trial, your subscription will automatically convert to a chosen paid plan and your payment method will be charged on that date. To avoid being charged, cancel before the trial ends in your account billing settings. We will email you at least three (3) days before the trial ends to remind you of the conversion.

26. Suspension and termination

We may suspend or terminate your access to the Services, in whole or in part, if:

you violate these Terms, including the rules in Section 17;

you fail to pay applicable fees;

your use creates legal, security, operational, or reputational risk;

we are required to do so by law or by a lawful request from an authority.

You may stop using the Services at any time. Termination does not relieve you of payment obligations already incurred.

27. Governing law and jurisdiction

These Terms are governed by the laws of Estonia, without regard to conflict-of-laws principles, except where mandatory consumer-protection law provides otherwise. Any dispute arising out of or relating to these Terms or the Services will be subject to the exclusive jurisdiction of the courts of Estonia, unless applicable law requires otherwise.

Consumers in the EEA, UK, or Switzerland. The choice of law above does not deprive you of the protection of mandatory provisions of the law of the country in which you have your habitual residence (Article 6 of Regulation (EC) No 593/2008 (Rome I) and corresponding national rules), and you retain the right to bring proceedings in the courts of your country of residence.

28. General provisions

Force majeure. Neither party is liable for failure or delay in performance caused by events beyond its reasonable control, including acts of God, war, terrorism, civil unrest, government action, epidemic or pandemic, labour disputes, internet or telecommunications failures, or failures of third-party hosting or payment infrastructure.

Notices. Notices to us must be sent to agent@heytrendy.app with a copy to Tähesaju tee 21-114, 13917 Tallinn, Estonia. We may give you notice by email to the address associated with your account or by in-product notification.

Assignment. You may not assign these Terms without our prior written consent. We may assign these Terms in connection with a merger, acquisition, financing, or sale of all or substantially all of our assets.

Severability. If any provision of these Terms is held unenforceable, that provision is severed and the remaining provisions remain in force.

Entire agreement. These Terms, together with any order form or checkout disclosures, constitute the entire agreement between you and us in respect of the Services and supersede prior agreements on the same subject.

Export controls and sanctions. You represent that you are not located in, and will not use the Services in or for the benefit of, any country or person subject to U.S., EU, or UK sanctions or export-control restrictions.

DMCA / copyright complaints. Notices of claimed copyright infringement should be sent to our designated agent at agent@heytrendy.app. Counter-notifications may be sent to the same address. We follow the procedures set out in 17 U.S.C. § 512.

Changes. We may update these Terms from time to time. If we make material changes, we will post the updated Terms on the website and update the Effective Date and Last Updated date. Your continued use of the Services after the updated Terms take effect constitutes acceptance of the revised Terms to the extent permitted by law.

29. Contact us

For all matters relating to these Terms, including privacy, security, billing, abuse, and legal notices:

SocialVibe OÜ
Tähesaju tee 21-114, 13917 Tallinn, Estonia

agent@heytrendy.app